Authorities believe the group is a successor to Royal, itself linked to the defunct Conti syndicate

U.S. and Europol officials announced on July 24, 2025, that a coordinated operation involving law enforcement from nine countries has led to the seizure of the darknet leak site operated by the BlackSuit ransomware gang. Authorities also reportedly dismantled part of the group’s digital infrastructure.

Active since spring 2023, BlackSuit did not operate under a Ransomware-as-a-Service (RaaS) model, meaning it neither leased its malware nor shared infrastructure with affiliates. A 2024 joint alert from the FBI and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) identified BlackSuit as an evolution of the Royal ransomware, which in turn is widely believed to have originated from Conti—a notorious Russian-speaking gang that dissolved in 2022.

According to U.S. authorities, BlackSuit is estimated to have demanded approximately $500 million (€426 million) in ransom payments over its operational lifespan.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.